US2017126654A1PendingUtilityA1

Method and system for dynamic password authentication based on quantum states

Assignee: ALIBABA GROUP HOLDING LTDPriority: Oct 28, 2015Filed: Oct 24, 2016Published: May 4, 2017
Est. expiryOct 28, 2035(~9.2 yrs left)· nominal 20-yr term from priority
Inventors:Yingfang Fu
H04L 63/083H04L 63/0435H04L 9/0852H04L 63/0869H04L 9/3271H04L 9/3273H04L 9/3226H04L 9/0858
38
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

One embodiment described herein provides a client-side process for performing dynamic-password authentication between a client and a server. This client-side process includes the steps of: generating, by the client, a service request comprising a first dynamic message; transmitting the first service request to the server; receiving a second dynamic message from the server in response to the first dynamic message for cross-validating the server; authenticating the second dynamic message to verify the validity of the server. If the validity of the server is verified, the client-side process further includes: generating a third dynamic message based on the second dynamic message; and transmitting the third dynamic message to the server for a final approval of the service request.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method for performing dynamic-password authentication between a client and a server, the method comprising:
 generating, by the client, a service request comprising a first dynamic message;   transmitting the first service request to the server;   receiving a second dynamic message from the server in response to the first dynamic message for cross-validating the server;   authenticating the second dynamic message to verify the validity of the server; and   if the validity of the server is verified,
 generating a third dynamic message based on the second dynamic message and the first dynamic message; and 
 transmitting the third dynamic message to the server for a final approval of the service request. 
   
     
     
         2 . The computer-implemented method of  claim 1 , wherein the first service request also includes identification information of the client. 
     
     
         3 . The computer-implemented method of  claim 1 , wherein the first dynamic message is encrypted with a symmetric key shared by the client and the server. 
     
     
         4 . The computer-implemented method of  claim 1 , wherein generating the first service request includes:
 randomly selecting one or more quantum state bases from a pre-installed quantum state basis library, wherein each quantum state basis in the quantum state basis library includes a set of orthogonal quantum states, and is associated with a unique quantum state identifier (QID);   assigning a random length value to each selected quantum state basis; and   forming the first dynamic message using QIDs and assigned length values of the selected quantum state bases.   
     
     
         5 . The computer-implemented method of  claim 4 , wherein authenticating the second dynamic message to verify the validity of the server includes:
 processing the second dynamic message to obtain a set of dynamic values;   comparing the set of dynamic values with a set of expected values based on the QIDs and length values included in the first dynamic message; and   if the set of dynamic values match the set of expected values, determining that the server is valid;   otherwise, determining that the server is invalid.   
     
     
         6 . The computer-implemented method of  claim 5 , wherein the second dynamic message includes a quantum bit string and an encrypted message, wherein the quantum bit string is generated by the server based on the QIDs and assigned length values in the first dynamic message, and wherein processing the second dynamic message includes:
 selecting a set of measurement bases based on the QIDs; and   measuring the received quantum bit string using the selected measurement bases to obtain a set of measurement results.   
     
     
         7 . The computer-implemented method of  claim 6 , wherein the set of expected values is indicated by the encrypted message, and wherein comparing the set of dynamic values with the set of expected values includes comparing the set of measurement results with the set of expected values to determine if the server is valid. 
     
     
         8 . The computer-implemented method of  claim 6 , wherein the third dynamic message includes the set of measurement results and a set of quantum state identifiers that identify quantum states used for obtaining the set of measurement results. 
     
     
         9 . A client device for performing dynamic-password authentication between the client device and a server, the client device comprising:
 a service request generator configured to generate a service request that includes a first dynamic message;   a service request transmitter configured to transmit the first dynamic message to the server;   a receiver configured to receive a second dynamic message from the server in response to the first dynamic message for cross-validating the server;   an authentication module configured to analyze the second dynamic message to verify the validity of the server;   a message generator configured to generate a third dynamic message based on the first and second dynamic messages in response to the server being valid; and   a message transmitter configured to transmit the third dynamic message to the server for a final approval of the service request.   
     
     
         10 . The client device of  claim 9 , further comprising a pre-installed quantum state basis library, wherein each quantum state basis in the quantum state basis library includes a set of orthogonal quantum states and is associated with a unique quantum state identifier (QID), and wherein the service request generator is configured to generate the service request by:
 randomly selecting one or more quantum state bases from the pre-installed quantum state basis library;   assigning a random length value to each selected quantum state basis; and   forming the first dynamic message using QIDs and assigned length values of the selected quantum state bases.   
     
     
         11 . The client device of  claim 9 , wherein the authentication module is configured to:
 process the second dynamic message to obtain a set of dynamic values;   compare the set of dynamic values with a set of expected values; and   if the set of dynamic values match the set of expected values, determine that the server is valid;   otherwise, determine that the server is invalid.   
     
     
         12 . The client device of  claim 11 , wherein the second dynamic message includes a quantum bit string and an encrypted message, wherein the quantum bit string is generated by the server based on the QIDs and assigned length values in the first dynamic message, and wherein while processing the second dynamic message, the authentication module is configured to:
 select a set of measurement bases based on the QIDs; and   measure the received quantum bit string using the selected measurement bases to obtain a set of measurement results.   
     
     
         13 . The client device of  claim 12 , wherein the set of expected values is indicated by the encrypted message, and wherein while comparing the set of dynamic values with the set of expected values, the authentication module compares the set of measurement results with the set of expected values to determine if the server is valid. 
     
     
         14 . The client device of  claim 12 , wherein the third dynamic message includes the set of measurement results and a set of quantum state identifiers that identify quantum states used for obtaining the set of measurement results. 
     
     
         15 . A computer-implemented method for performing dynamic-password authentication between a client and a server, the method comprising:
 receiving, by the server, a service request comprising a first dynamic message and identity information from the client;   verifying the validity of the client based on the identity information; and   if the validity of the client is verified,
 processing the first dynamic message to obtain a set of dynamic information; 
 generating a second dynamic message based on the set of dynamic information; and 
 transmitting the second dynamic message to the client to allow the client to cross-validate the server. 
   
     
     
         16 . The computer-implemented method of  claim 15 , wherein the first dynamic message includes a set of quantum state basis identifiers (QIDs) and a set of length values, with each length value corresponding to a QID, wherein each QID corresponds to a quantum state basis in a quantum state basis library pre-installed on both the client and the server, and wherein each quantum state basis includes a set of orthogonal quantum states. 
     
     
         17 . The computer-implemented method of  claim 16 , wherein obtaining the set of dynamic information includes obtaining the set of QIDs and length values. 
     
     
         18 . The computer-implemented method of  claim 17 , wherein generating the second dynamic message based on the set of dynamic information includes:
 generating a random binary bit string, wherein a length of the random binary bit string is the sum of the length values;   generating a quantum bit string from the random binary bit string based on the obtained QIDs and length values; and   generating a set of decimal numbers from the random binary bit string based on the length values.   
     
     
         19 . The computer-implemented method of  claim 18 , further comprising encrypting the set of decimal numbers using a symmetric key shared by the client and the server. 
     
     
         20 . The computer-implemented method of  claim 15 , further comprising:
 receiving a third dynamic message in response to the second dynamic message from the client;   analyzing the third dynamic message to further determine the validity of the client; and   if so, authorizing the service request;   otherwise, denying the service request.   
     
     
         21 . The computer-implemented method of  claim 20 , wherein the third dynamic message includes a measurement result of a quantum bit string included in the second dynamic message, wherein the measurement result is obtained by the client based on information included in the first dynamic message. 
     
     
         22 . A server for performing dynamic-password authentication between a client and the server, the server comprising:
 a service request receiver configured to receive a service request comprising a first dynamic message and identity information from the client;   a verifying module configured to verify the validity of the client based on the identity information;   a service request processing module configured to process the first dynamic message to obtain a set of dynamic information;   a message generator configured to generate a second dynamic message based on the set of dynamic information; and   a message transmitter configured to transmit the second dynamic message to the client to allow the client to cross-validate the server.   
     
     
         23 . The server of  claim 22 , further comprising a pre-installed quantum state basis library, wherein the first dynamic message includes a set of quantum state basis identifiers (QIDs) and a set of length values, with each length value corresponding to a quantum state basis, wherein each QID corresponds to a quantum state basis in the pre-installed quantum state basis library, and wherein each quantum state basis includes a set of orthogonal quantum states. 
     
     
         24 . The server of  claim 23 , wherein the set of dynamic information includes the set of QIDs and length values. 
     
     
         25 . The server of  claim 24 , wherein while generating the second dynamic message, the message generator is configured to:
 generate a random binary bit string, wherein a length of the random binary bit string is the sum of the length values;   generate a quantum bit string from the random binary bit string based on the obtained QIDs and length values; and   generate a set of decimal numbers from the random binary bit string based on the length values.   
     
     
         26 . The server of  claim 25 , further comprising an encryption module configured to encrypt the set of decimal numbers using a symmetric key shared by the client and the server. 
     
     
         27 . The server of  claim 22 , further comprising:
 a message receiving module configured to receive a third dynamic message in response to the second dynamic message from the client;   an analyzing module configured to analyzing the third dynamic message to further determine the validity of the client; and   an authorization module configured to authorizing the service request in response to the analyzing module determining that the client is valid.   
     
     
         28 . The server of  claim 27 , wherein the third dynamic message includes a measurement result of a quantum bit string included in the second dynamic message, wherein the measurement result is obtained by the client based on information included in the first dynamic message.

Join the waitlist — get patent alerts

Track US2017126654A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.